mirror of
https://github.com/BookStackApp/BookStack.git
synced 2026-07-21 05:33:52 +03:00
/tmp filled with bszip-###### #5090
Closed
opened 2026-02-05 09:39:19 +03:00 by OVERLORD
·
5 comments
No Branch/Tag Specified
development
l10n_development
release
snyk-action
ci_and_static
mfa_key
phpstan_june26
MilnerMart/development
GamerClassN7/impersonations-for-admin
Zhey-on/feature/csp-image-css-controls-6033
tortillas5/development
llm_only
vectors
McTom234/oidc-key-algorithms
captcha_example
v26.05.2
v26.05.1
v26.05
v26.03.5
v26.03.4
v26.03.3
v26.03.2
v26.03.1
v26.03
v25.12.9
v25.12.8
v25.12.7
v25.12.6
v25.12.5
v25.12.4
v25.12.3
v25.12.2
v25.12.1
v25.12
v25.11.6
v25.11.5
v25.11.4
v24.11.4
v25.11.3
v25.11.2
v25.11.1
v25.11
v25.07.3
v25.07.2
v25.07.1
v25.07
v25.05.2
v25.05.1
v25.05
v25.02.5
v25.02.4
v25.02.3
v25.02.2
v25.02.1
v25.02
v24.12.1
v24.12
v24.10.3
v24.10.2
v24.10.1
v24.10
v24.05.4
v24.05.3
v24.05.2
v24.05.1
v24.05
v24.02.3
v24.02.2
v24.02.1
v24.02
v23.12.3
v23.12.2
v23.12.1
v23.12
v23.10.4
v23.10.3
v23.10.2
v23.10.1
v23.10
v23.08.3
v23.08.2
v23.08.1
v23.08
v23.06.2
v23.06.1
v23.06
v23.05.2
v23.05.1
v23.05
v23.02.3
v23.02.2
v23.02.1
v23.02
v23.01.1
v23.01
v22.11.1
v22.11
v22.10.2
v22.10.1
v22.10
v22.09.1
v22.09
v22.07.3
v22.07.2
v22.07.1
v22.07
v22.06.2
v22.06.1
v22.06
v22.04.2
v22.04.1
v22.04
v22.03.1
v22.03
v22.02.3
v22.02.2
v22.02.1
v22.02
v21.12.5
v21.12.4
v21.12.3
v21.12.2
v21.12.1
v21.12
v21.11.3
v21.11.2
v21.11.1
v21.11
v21.10.3
v21.10.2
v21.10.1
v21.10
v21.08.6
v21.08.5
v21.08.4
v21.08.3
v21.08.2
v21.08.1
v21.08
v21.05.4
v21.05.3
v21.05.2
v21.05.1
v21.05
v21.04.6
v21.04.5
v21.04.4
v21.04.3
v21.04.2
v21.04.1
v21.04
v0.31.8
v0.31.7
v0.31.6
v0.31.5
v0.31.4
v0.31.3
v0.31.2
v0.31.1
v0.31.0
v0.30.7
v0.30.6
v0.30.5
v0.30.4
v0.30.3
v0.30.2
v0.30.1
v0.30.0
v0.29.3
v0.29.2
v0.29.1
v0.29.0
v0.28.3
v0.28.2
v0.28.1
v0.28.0
v0.27.5
v0.27.4
v0.27.3
v0.27.2
v0.27.1
v0.27
v0.26.4
v0.26.3
v0.26.2
v0.26.1
v0.26.0
v0.25.5
v0.25.4
v0.25.3
v0.25.2
v0.25.1
v0.25.0
v0.24.3
v0.24.2
v0.24.1
v0.24.0
v0.23.2
v0.23.1
v0.23.0
v0.22.0
v0.21.0
v0.20.3
v0.20.2
v0.20.1
v0.20.0
v0.19.0
v0.18.5
v0.18.4
v0.18.3
v0.18.2
v0.18.1
v0.18.0
v0.17.4
v0.17.3
v0.17.2
v0.17.1
v0.17.0
v0.16.3
v0.16.2
v0.16.1
v0.16.0
v0.15.3
v0.15.2
v0.15.1
v0.15.0
v0.14.3
v0.14.2
v0.14.1
v0.14.0
v0.13.1
v0.13.0
v0.12.2
v0.12.1
v0.12.0
v0.11.2
v0.11.1
v0.11.0
v0.10.0
v0.9.3
v0.9.2
v0.9.1
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.6
v0.7.5
v0.7.4
v0.7.3
0.7.2
v.0.7.1
v0.7.0
v0.6.3
v0.6.2
v0.6.1
v0.6.0
v0.5.0
Labels
Clear labels
🎨 Design
📖 Docs Update
🐛 Bug
🐛 Bug
:cat2:🐈 Possible duplicate
💿 Database
☕ Open to discussion
💻 Front-End
🐕 Support
🚪 Authentication
🌍 Translations
🔌 API Task
🏭 Back-End
⛲ Upstream
🔨 Feature Request
🛠️ Enhancement
🛠️ Enhancement
🛠️ Enhancement
❤️ Happy feedback
🔒 Security
🔍 Pending Validation
💆 UX
📝 WYSIWYG Editor
🌔 Out of scope
🔩 API Request
:octocat: Admin/Meta
🖌️ View Customization
❓ Question
🚀 Priority
🛡️ Blocked
🚚 Export System
♿ A11y
🔧 Maintenance
> Markdown Editor
pull-request
Mirrored from GitHub Pull Request
No Label
🐛 Bug
Milestone
No items
No Milestone
Projects
Clear projects
No project
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: starred/BookStack#5090
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @JtheBAB on GitHub (Dec 28, 2024).
Describe the Bug
I upgraded a few days before to 24.12 and now my /tmp is full with a lot of files like:
-rw------- 1 www-data www-data 131704 Dec 26 19:56 bszip-zjPTTH
-rw------- 1 www-data www-data 11347585 Dec 27 19:56 bszip-ZlGVV9
-rw------- 1 www-data www-data 1797 Dec 26 11:56 bszip-zmQv5W
-rw------- 1 www-data www-data 1356 Dec 26 03:56 bszip-ZnG94v
-rw------- 1 www-data www-data 78599 Dec 26 03:56 bszip-zo1YiQ
-rw------- 1 www-data www-data 719 Dec 26 11:56 bszip-zo6xRj
-rw------- 1 www-data www-data 25234 Dec 26 19:56 bszip-ZobfbT
-rw------- 1 www-data www-data 25236 Dec 26 23:56 bszip-ZQFTFx
-rw------- 1 www-data www-data 19664 Dec 28 03:57 bszip-zrvqwX
-rw------- 1 www-data www-data 19666 Dec 27 03:56 bszip-zSwzym
-rw------- 1 www-data www-data 1160 Dec 27 07:56 bszip-zt8YxX
-rw------- 1 www-data www-data 31438858 Dec 27 23:56 bszip-zufGgj
-rw------- 1 www-data www-data 0 Dec 28 11:56 bszip-zYAjYr
-rw------- 1 www-data www-data 1372 Dec 25 23:57 bszip-zZAkKm
-rw------- 1 www-data www-data 7707551 Dec 27 15:56 bszip-zzex3O
-rw------- 1 www-data www-data 381 Dec 26 23:56 bszip-ZZnwjc
-rw------- 1 www-data www-data 802216 Dec 25 23:57 bszip-ZzRR3m
When i unzip it than i can see that is random content from my bookstack instance.
I also see this:
-rw------- 1 www-data www-data 397305 Dec 21 19:55 bs-pdfgen-html-00j56x
-rw------- 1 www-data www-data 22275 Dec 21 03:56 bs-pdfgen-html-00Rg25
-rw------- 1 www-data www-data 55713 Dec 19 19:56 bs-pdfgen-html-01hIYc
-rw------- 1 www-data www-data 132196 Dec 27 11:56 bs-pdfgen-html-023StT
-rw------- 1 www-data www-data 397305 Dec 23 03:55 bs-pdfgen-html-04EyQT
-rw------- 1 www-data www-data 0 Dec 28 11:56 bs-pdfgen-html-06Md6w
-rw------- 1 www-data www-data 0 Dec 28 11:56 bs-pdfgen-html-06P4IX
-rw------- 1 www-data www-data 8529630 Dec 26 07:55 bs-pdfgen-html-0c6wnA
-rw------- 1 www-data www-data 20693 Dec 24 23:56 bs-pdfgen-html-0deTtg
-rw------- 1 www-data www-data 22919 Dec 21 03:56 bs-pdfgen-html-0DqgSL
-rw------- 1 www-data www-data 397305 Dec 23 23:56 bs-pdfgen-html-0fOOfE
-rw------- 1 www-data www-data 90275 Dec 21 11:55 bs-pdfgen-html-0fs1cD
I really doubt that someone export random pages from Bookstack (at least nothing in the audit log - if logged at all). Any idea what that could be?
Steps to Reproduce
I just updated and then a few days later i got the message from my monitoring system that the /tmp is full
Expected Behaviour
It should only create a file when needed. Cleanup old files?
Screenshots or Additional Context
No response
Browser Details
No response
Exact BookStack Version
v24.12
@ssddanbrown commented on GitHub (Dec 30, 2024):
Hi @JtheBAB,
I've probably been a bit lazy in regard to ensuring temp files are cleaned (assuming they'd be cleaned up by the system) but we should improve that for scenarios where they aren't cleaned as often.
Is your instance publicly accessible?
Exports are not logged in the audit log (same as other read-only activity) but access to exports can be controlled via role permissions.
@JtheBAB commented on GitHub (Dec 30, 2024):
Some books are available without authentication but not public like internet access. What i find strange that i have regular the same exports during the same time of a day. Like something would trigger that export.
I removed now the export functionality for the Public user.
@ssddanbrown commented on GitHub (Dec 31, 2024):
Strange, if needed you might be able to use webserver access logs to track back who was requesting these exports.
I've assigned this for the next patch, and started work in #5379 where I also plan to also add better cleanup for PDF exports.
@JtheBAB commented on GitHub (Jan 2, 2025):
I found now what is responsible. We have a internal Sharepoint instances that crawls also the bookstack instance. And it looks like that can trigger the export:
XXX.XXX.XXX.XX - - [29/Dec/2024:23:57:13 +0100] "GET /books/#####/######/export/zip HTTP/1.1" 200 7771476 "-" "Mozilla/4.0 (compatible; MSIE 4.01; Windows NT; MS Search 6.0 Robot)"
XXX.XXX.XXX.XX - - [29/Dec/2024:23:57:15 +0100] "GET /books/#####/######/export/zip HTTP/1.1" 200 54202 "-" "Mozilla/4.0 (compatible; MSIE 4.01; Windows NT; MS Search 6.0 Robot)"
XXX.XXX.XXX.XX - - [29/Dec/2024:23:57:15 +0100] "GET /books/#####/######/export/zip HTTP/1.1" 200 81087 "-" "Mozilla/4.0 (compatible; MSIE 4.01; Windows NT; MS Search 6.0 Robot)"
XXX.XXX.XXX.XX - - [29/Dec/2024:23:57:15 +0100] "GET /books/#####/######/export/zip HTTP/1.1" 200 3892 "-" "Mozilla/4.0 (compatible; MSIE 4.01; Windows NT;
MS Search 6.0 Robot)"
Don't now if "just" crawling should trigger the export.
@ssddanbrown commented on GitHub (Jan 5, 2025):
Crawling is just fetching as a user would, so we'd have to actively be defensive (use other HTTP methods) to avoid that.
Alternatively the robots.txt could maybe be customized to avoid the bot fetching export URLs, if it listens to robots.txt files.
Either way, I've now added more substantial cleanup for exports in #5379 which will be part of the next patch release, so I'll therefore close this off.